ESET Online Help

Search
Select the category
Select the topic

Technical details for ESET Endpoint Encryption and Windows feature updates

Install Windows feature updates while Full Disk Encryption is installed.

Solution

To install Windows Feature updates on a Full Disk Encrypted system, the encryption drivers must be made available to Windows during the update. ESET Endpoint Encryption includes a file SetupConfig.ini stored inside the following directory:

C:\Users\Default\AppData\Local\Microsoft\Windows\WSUS\

If you are using a custom SetupConfig.ini file as part of your update process, ensure it has been fully tested alongside FDE.

The SetupConfig.ini file passes /reflectdrivers to Windows during the update process, which passes the encryption driver to Windows to access the disk correctly during the update. Without this switch, Windows cannot read the disk correctly due to the encryption, and the update process will fail.

After Windows successfully installs an update, the Postoobe switch runs a script. The Postoobe script creates the necessary entries to allow Windows to update correctly again in the future.

The ESET Endpoint Encryption Windows Update utility uses the /ConfigFile switch to point Windows toward the SetupConfig.ini file.

Additional information

Visit the following Microsoft articles:

Windows Setup Automation Overview

Windows Setup Command Line Options